MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d4dcb3929715ff78ff420dd4f1a3ee6a7b9056f2f22be44fe06992935f7eb1c0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: d4dcb3929715ff78ff420dd4f1a3ee6a7b9056f2f22be44fe06992935f7eb1c0
SHA3-384 hash: 78e2fe8489f2a8c24fa4ba5ae3193aed867361317bbcc4365a655949de6a7de2cf3d69bf5b670899032eb5ddd95cca7c
SHA1 hash: 3a094d45415888cdfe919970c1f0980fbc605449
MD5 hash: 55c1affce5a02073667c1c33e7c1c130
humanhash: connecticut-potato-eleven-table
File name:c.sh
Download: download sample
Signature Mirai
File size:849 bytes
First seen:2025-01-10 02:06:48 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:Wr/yQInJRNIyxk2OKUX+DwZlsu6/NedeXn:q/UhlOiqNmNwqn
TLSH T142019BCE2D70755A0840DDC426A19840BC0AFEEAD4969B4EF5C8CE3D56C8B14702EFCB
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://79.124.60.186/bins/res.arm368d9c9d203dc9e6047e7f00c6c92cfdbb845348bc7516dfd0569ed3cda16f1c Miraielf mirai opendir
http://79.124.60.186/bins/res.arm5b893ec14f82f0111a82adb81c4ff326af075a594f9ed4443eb0de2346ef03aaf Miraielf mirai opendir
http://79.124.60.186/bins/res.arm6eff81e483d964da558eb9214e743b85ea4b4cd8f0c24f4c0c1638f8f6bb557bc Miraielf mirai opendir
http://79.124.60.186/bins/res.arm7c74dde32c0a93bb5ec5cc8457d88e9d3d4d4eeb83343c573e7d6b3669d695621 Miraielf mirai opendir
http://79.124.60.186/bins/res.sh483f662eb487b31559891eeaea6dd0c1ffa41cb0aa95aef6c202cc64c7e4ee7d8 Miraielf mirai opendir
http://79.124.60.186/bins/res.arcbf99d3657d63527df883f84094abd43f1b1e86583df631b06a3b47ba920066e8 Miraielf mirai opendir
http://79.124.60.186/bins/res.mips35a176fd312afaacdf56f8f53a2a4e4ecc83d737278744d0d0a9c057ddd602bc Miraielf mirai opendir
http://79.124.60.186/bins/res.mpslee2fa2c8dd0670fca4e137cbb60675dcdc6148f799644667377273bb1e7d1ab4 Miraielf mirai opendir
http://79.124.60.186/bins/res.spc6d28dc487c2cee5e779f0bfd8430b96f282ec1473eac0dcc529fbbb7b43ba6bf Miraielf mirai opendir
http://79.124.60.186/bins/res.x862d8fea0d43cdd0c083cf4d94267390fb91e82fc95af76865051f6d1d1214424e Mirai32-bit elf mirai x86-32

Intelligence


File Origin
# of uploads :
1
# of downloads :
113
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
92.5%
Tags:
downloader agent overt
Result
Verdict:
UNKNOWN
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2025-01-10 03:02:52 UTC
AV detection:
11 of 24 (45.83%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh d4dcb3929715ff78ff420dd4f1a3ee6a7b9056f2f22be44fe06992935f7eb1c0

(this sample)

  
Delivery method
Distributed via web download

Comments